A method, apparatus, and device for implementing secure communication between devices
By using quantum security information equipment to generate quantum random numbers as keys in wireless communication networks, the problem that the random number encryption method in the prior art cannot fully guarantee communication security, and high security and confidentiality of communication data are achieved.
Patent Information
- Application Number
- CN202211329442.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-10-27
AI Technical Summary
The random number encryption method used in existing wireless communication networks cannot fully guarantee communication security, especially pseudo-random numbers are easily predicted, and the application range of physical random number generators is limited.
The quantum security information device is connected to the communication device, and a quantum random number is generated as the key. The first quantum private key and public key are generated through the quantum key, and encryption and decryption operations are performed to ensure the security of the communication data.
By using quantum random numbers, the true randomness of communication data is achieved, which cannot be predicted, ensuring the security of the key, thereby greatly improving the confidentiality and security of communication.
Smart Images

Figure CN115694804B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security, and particularly to a method, device, and equipment for realizing secure communication between devices. Background Art
[0002] In recent years, technologies for wiretapping wired and wireless calls and voice recognition have developed significantly, resulting in the leakage of various personal information including technical information, causing economic or social problems. In particular, smartphones, web conferences, etc. are vulnerable to hacking and wiretapping, and the security of wireless communication networks cannot be guaranteed.
[0003] Currently, data transmitted over wireless communication networks can be encrypted using random numbers. Based on the generation method and the characteristics of the output sequence, the generation methods of random numbers can be divided into two categories: pseudo-random number generators and physical random number generators. However, since pseudo-random numbers are generated based on a deterministic algorithm, the source of their randomness is only the randomness of the input seed. Therefore, when it is used frequently, it can theoretically be predicted by statistical analysis of the generated random numbers. Thus, when using pseudo-random numbers to encrypt data transmitted over wireless communication networks, the security cannot be fully guaranteed. And the application scope of physical random number generators is limited. Therefore, how to achieve secure communication between communication devices and avoid information leakage is an urgent problem to be solved. Summary of the Invention
[0004] In view of this, embodiments of the present application provide a method, device, and equipment for realizing secure communication between devices, which can achieve true randomness of random numbers during the data transmission process of wireless communication networks, making them unpredictable, and ensuring that when using such random number sources as key sources, the keys themselves are provably secure, thereby ensuring the security of communication data.
[0005] In a first aspect, embodiments of the present application provide a method for realizing secure communication between devices. The method is applied to a first quantum security information device, which is connected to a first communication device. The method includes:
[0006] Generating a quantum random number as a quantum key, and generating a first quantum private key and a first quantum public key according to the quantum key;
[0007] Sending the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to a second quantum security information device connected to a second communication device;
[0008] Receiving a second quantum public key from the first communication device, where the second quantum public key is sent by the second quantum security information device to the first communication device through the second communication device;
[0009] After receiving the second encrypted data sent by the second communication device, decrypt the second encrypted data using the first quantum private key, where the second encrypted data is generated by the second quantum security information device using the first quantum public key;
[0010] When the data to be encrypted is collected, encrypt the data to be encrypted using the second quantum public key to generate the first encrypted data and send it to the first communication device, so that the first communication device sends the first encrypted data to the second quantum security information device.
[0011] Optionally, the method for implementing secure communication between devices further includes:
[0012] After the first quantum security information device is connected to the first communication device, authenticate whether the user corresponding to the first communication device is legal. If the user is legal, establish a data channel with the first communication device.
[0013] Optionally, the method for implementing secure communication between devices further includes:
[0014] When the communication data volume of the data to be encrypted collected exceeds the communication data threshold, generate the first quantum private key and the first quantum public key according to the quantum key;
[0015] Send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to the second quantum security information device connected to the second communication device;
[0016] Receive the encrypted symmetric key from the first communication device, where the encrypted symmetric key is generated by the second quantum security information device using the first quantum public key to encrypt the symmetric key random number, and the symmetric key random number is generated by the second quantum security information device connected to the second communication device;
[0017] Decrypt the encrypted symmetric key using the first quantum private key to obtain the symmetric key;
[0018] When the data to be encrypted is collected, encrypt the data to be encrypted using the symmetric key to generate the third encrypted data and send it to the first communication device, so that the first communication device sends the third encrypted data to the second communication device;
[0019] After receiving the fourth encrypted data sent by the second communication device, decrypt the fourth encrypted data using the symmetric key, where the fourth encrypted data is generated by the second quantum security information device using the symmetric key.
[0020] Optionally, the method for implementing secure communication between devices further includes:
[0021] When it is determined that the device secure communication process ends, destroy the first quantum public key, the first quantum private key, the second quantum public key, and the second quantum private key.
[0022] Optionally, the method for implementing secure communication between devices further includes:
[0023] When it is determined that the device secure communication process ends, destroy the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key.
[0024] Optionally, generating the first quantum private key and the first quantum public key according to the quantum key includes:
[0025] Using an algorithm including a hash algorithm, a public key cryptography algorithm, and / or a symmetric cryptography algorithm to generate the first quantum private key and the first quantum public key according to the quantum key.
[0026] In a second aspect, an embodiment of the present application provides a device for implementing secure communication between devices, which is applied to a first quantum security information device. The first quantum security information device is connected to a first communication device. The device includes:
[0027] A generating unit, configured to generate a quantum random number as a quantum key, and generate a first quantum private key and a first quantum public key according to the quantum key;
[0028] A sending unit, configured to send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to a second quantum security information device connected to a second communication device;
[0029] A receiving unit, configured to receive a second quantum public key from the first communication device, where the second quantum public key is sent by the second quantum security information device to the first communication device through the second communication device;
[0030] A decrypting unit, configured to decrypt the second encrypted data using the first quantum private key when receiving the second encrypted data sent by the second communication device, where the second encrypted data is generated by the second quantum security information device using the first quantum public key;
[0031] An encrypting unit, configured to encrypt the data to be encrypted using the second quantum public key when collecting the data to be encrypted, generate first encrypted data and send it to the first communication device, so that the first communication device sends the first encrypted data to the second quantum security information device.
[0032] Optionally, the apparatus for implementing secure communication between devices further includes:
[0033] A data channel establishment unit, configured to, after the first quantum secure information device is connected to the first communication device, authenticate whether the user corresponding to the first communication device is legal, and if the user is legal, establish a data channel with the first communication device.
[0034] Optionally, the apparatus for implementing secure communication between devices further includes:
[0035] A transmission unit exceeding the threshold, configured to, when the communication data volume of the data to be encrypted collected exceeds the communication data threshold, generate the first quantum private key and the first quantum public key according to the quantum key;
[0036] Send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to the second quantum secure information device connected to the second communication device;
[0037] Receive the encrypted symmetric key from the first communication device, where the encrypted symmetric key is generated by the second quantum secure information device using the first quantum public key to encrypt the symmetric key random number, and the symmetric key random number is generated by the second quantum secure information device connected to the second communication device;
[0038] Decrypt the encrypted symmetric key using the first quantum private key to obtain the symmetric key;
[0039] When the data to be encrypted is collected, encrypt the data to be encrypted using the symmetric key to generate the third encrypted data and send it to the first communication device, so that the first communication device sends the third encrypted data to the second communication device;
[0040] When the fourth encrypted data sent by the second communication device is received, decrypt the fourth encrypted data using the symmetric key, where the fourth encrypted data is generated by the second quantum secure information device using the symmetric key.
[0041] In a third aspect, an embodiment of the present application provides a device for implementing secure communication between devices, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for secure mobile communication based on quantum random numbers described in the foregoing first aspect is implemented.
[0042] A method, apparatus, and device for implementing secure communication between devices provided by an embodiment of the present application. The method is applied to a first quantum secure information device, which is connected to a first communication device. First, a quantum random number is generated as a quantum key, and a first quantum private key and a first quantum public key are generated according to the quantum key. Second, the first quantum public key is sent to the first communication device, so that the first communication device sends the first quantum public key to a second quantum secure information device connected to a second communication device, and the second quantum public key is received from the first communication device. The second quantum public key is sent by the second quantum secure information device to the first communication device through the second communication device. Third, after receiving the second encrypted data sent by the second communication device, the second encrypted data is decrypted using the first quantum private key. The second encrypted data is generated by the second quantum secure information device using the first quantum public key. Finally, when the data to be encrypted is collected, the data to be encrypted is encrypted using the second quantum public key to generate first encrypted data and sent to the first communication device, so that the first communication device sends the first encrypted data to the second quantum secure information device. In this way, when communication devices interact, communication data is encrypted using quantum random numbers, and quantum random numbers cannot be predicted, greatly improving communication security. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] To more clearly illustrate the technical solutions in this embodiment or the prior art, the following will briefly introduce the drawings required for the description of the embodiment or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0044] Figure 1 An architecture diagram of a method for implementing secure communication between devices provided by an embodiment of the present application;
[0045] Figure 2 A flowchart of a method for implementing secure communication between devices provided by an embodiment of the present application;
[0046] Figure 3 An interaction diagram of a method for implementing secure communication between devices provided by an embodiment of the present application;
[0047] Figure 4 A flowchart of another method for implementing secure communication between devices provided by an embodiment of the present application;
[0048] Figure 5 An interaction diagram of another method for implementing secure communication between devices provided by an embodiment of the present application;
[0049] Figure 6 A flowchart of a method for implementing secure communication between devices in an embodiment of this application scenario;
[0050] Figure 7 A schematic structural diagram of a device for implementing secure communication between devices provided in an embodiment of this application;
[0051] Figure 8 A schematic diagram of the corresponding device and computer storage medium provided in an embodiment of this application. Detailed implementation manners
[0052] To make the above objects, features, and advantages of this application more obvious and understandable, the embodiments of this application will be further described in detail below with reference to the drawings and specific implementation manners.
[0053] To facilitate the understanding and explanation of the technical solution provided in the embodiment of this application, the background technology of this application will be described first below.
[0054] After researching the random number generation method, the inventors found that since the pseudo-random number is generated based on a deterministic algorithm and its randomness source is only the randomness of the input seed, when it is frequently used, it can theoretically be predicted by statistical analysis of the generated random numbers. The randomness of physical random numbers is based on the randomness of some non-deterministic objective physical phenomena, including atmospheric noise, electronic noise, circuit jitter, etc. These random number generators generate random numbers from the results of detecting these physical phenomena. However, the existing random number encryption methods cannot fully guarantee the security of communication, and there are still security vulnerabilities.
[0055] Based on this, this application uses a quantum secure information device connected to a communication device to generate a quantum key. Among them, the quantum key includes a quantum public key and a quantum private key. During the communication process, the first quantum public key is sent to the first communication device, and then the first communication device sends the first quantum public key to the second quantum secure information device connected to the second communication device. Similarly, the first quantum secure information device receives the second quantum public key sent by the second quantum secure information device through the second communication device, decrypts the second encrypted data sent by the second communication device using the first quantum private key, encrypts the data to be encrypted with the second quantum public key to generate the first encrypted data and sends it to the first communication device, and then sends it to the second quantum secure information device.
[0056] In the embodiment of this application, quantum random numbers are generally considered to have true randomness and cannot be predicted. They are an ideal random number generator. When using this type of random number source as the key source, the key itself is provably secure, and the data security of communication is guaranteed.
[0057] SeeFigure 1 , this figure is an architecture diagram for implementing a secure communication method between devices in an embodiment of the present application. The architecture includes:
[0058] A first quantum-secure information device, a first communication device, a second quantum-secure information device, and a second communication device.
[0059] The first quantum-secure information device is used to collect communication data of a first user connected to the first quantum-secure information device. After the first quantum-secure information device collects the data to be encrypted, it uses a second quantum private key to encrypt the data to be encrypted, generates first encrypted data, and then sends the first encrypted data to the first communication device. The first communication device and the second communication device perform communication interaction, where the second communication device receives communication data of a second user played by the second quantum-secure information device and connected to the second quantum-secure information device.
[0060] The first quantum-secure information device and the first communication device can be connected by means such as Bluetooth, WiFi, or near-field communication, but are not limited to the above connection methods.
[0061] It should be noted that after the communication interaction ends, the keys of the communication interaction will all be destroyed.
[0062] See Figure 2 , this figure is a flowchart of a method for implementing secure communication between devices provided by an embodiment of the present application. The method includes steps S201 - S206:
[0063] It should be noted that in an embodiment of the present application, the method is applied to the first quantum-secure information device, and the first quantum-secure information device is connected to the first communication device.
[0064] In this embodiment, two communication devices are taken as an example, but the present application is not limited to the communication between two communication devices.
[0065] In this embodiment, after the first quantum-secure information device is connected to the first communication device, it authenticates whether the user corresponding to the first communication device is legal. If the user is legal, a data channel is established with the first communication device.
[0066] In an embodiment of the present application, the connection method between the first quantum-secure information device and the first communication device is not limited. It can be connected by means such as WiFi, Bluetooth, or near-field communication. After connection, mutual authentication through certificates is required to establish data channel 1. The first communication device can confirm the legality of the user through methods such as user password or face recognition.
[0067] In the embodiments of the present application, the connection method between the second quantum secure information device and the second communication device is not limited. It can be connected through methods such as WiFi, Bluetooth, or near field communication. After the connection, a data channel 2 is established after mutual authentication with certificates. The second communication device can confirm the legitimacy of the user through methods such as user password or face recognition.
[0068] S201: The first quantum secure information device generates a quantum random number as the first quantum key, and generates a first quantum private key and a first quantum public key according to the first quantum key.
[0069] In this embodiment, the first quantum key is generated by a first quantum random number generator, and the first quantum public key and the first quantum private key are generated from the first quantum key through a public key cryptography algorithm.
[0070] In this embodiment, by using algorithms including a hash algorithm, a public key cryptography algorithm, and / or a symmetric cryptography algorithm, a first quantum private key and a first quantum public key are generated according to the quantum key.
[0071] S202: Send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to the second quantum secure information device connected to the second communication device.
[0072] In this embodiment, the first quantum public key is transmitted to the first communication device, and after receiving the first quantum public key, the first communication device sends the first quantum public key to the second quantum secure information device connected to the first communication device.
[0073] S203: Receive a second quantum public key from the first communication device, where the second quantum public key is sent by the second quantum secure information device to the first communication device through the second communication device.
[0074] Among them, the implementation of this step may include:
[0075] S203a: The second quantum secure information device generates a quantum random number as the second quantum key, and generates a second quantum private key and a second quantum public key according to the second quantum key.
[0076] In this embodiment, the second quantum key is generated by a second quantum random number generator in the second quantum secure information device, and the second quantum public key is generated from the second quantum key through a public key cryptography algorithm.
[0077] S203b: The second quantum secure information device sends the second quantum public key to the second communication device, so that the second communication device sends the second quantum public key to the first quantum secure information device connected to the first communication device.
[0078] In this embodiment, the second quantum public key is transmitted to the second communication device. After receiving the second quantum public key, the second communication device sends the second quantum public key to the first quantum security information device connected to the second communication device.
[0079] S204: After receiving the second encrypted data sent by the second communication device, use the first quantum private key to decrypt the second encrypted data, where the second encrypted data is generated by the second quantum security information device using the first quantum public key.
[0080] In this embodiment, after receiving the second quantum public key, the second communication device sends the second quantum public key to the first communication device using a traditional communication network such as a public wireless network or an optical fiber network. The second encrypted data is generated by the second quantum security information device using the first quantum public key.
[0081] S205: When the first quantum security information device collects the data to be encrypted of User 1, use the second quantum public key to encrypt the data to be encrypted, and generate the first encrypted data to send to the first communication device.
[0082] In this embodiment, after the first quantum security information device collects the data to be encrypted of User 1, use the second quantum public key sent by the second quantum security information device to the first communication device through the second communication device to encrypt the data. The encrypted data is called the first encrypted data, and the first encrypted data is sent to the first communication device.
[0083] S206: The first communication device sends the first encrypted data to the second quantum security information device, and the second quantum security information device decrypts the first encrypted data using the second quantum private key.
[0084] In this embodiment, after the first communication device receives the first encrypted data, it sends it to the second quantum security information device through wireless network communication or optical fiber communication, etc. The second quantum security information device decrypts the first encrypted data using the second quantum private key with a decryption algorithm and plays it to User 2.
[0085] Based on the above content, it is possible to achieve the true randomness of random numbers, which cannot be predicted. Communicate in the data channel, use their respective private keys to decrypt the received public keys of the other party, and greatly improve the confidentiality and security of communication.
[0086] See Figure 3 , which is an interaction diagram of a method for implementing secure communication between devices provided by an embodiment of this application.
[0087] In this embodiment, the first communication device and the second communication device perform device - to - device interaction. Since the content of the interaction data needs to be kept confidential, the following steps are included in the interaction process:
[0088] S301: The first quantum - secure information device generates a first quantum public key and a first quantum private key.
[0089] S302: After the first communication device receives the first quantum public key sent by the first quantum - secure information device, it sends the first quantum public key to the second quantum - secure information device for storage.
[0090] S303: After the first quantum - secure information device receives the second quantum public key generated by the second quantum - secure information device and received by the second communication device, it stores the second quantum public key in the first quantum - secure information device.
[0091] S304: The first quantum - secure information device receives the second encrypted data sent by the second quantum - secure information device.
[0092] S305: When receiving the second encrypted data sent by the second communication device, use the first quantum private key to decrypt the second encrypted data.
[0093] Among them, the second encrypted data is generated by the second quantum - secure information device using the first quantum public key.
[0094] S306: When the data to be encrypted is collected, use the second quantum public key to encrypt the data to be encrypted, generate the first encrypted data and send it to the first communication device, so that the first communication device sends the first encrypted data to the second communication device.
[0095] S307: When the secure communication process ends, destroy the first quantum public key, the first quantum private key, the second quantum private key, and the second quantum public key.
[0096] When the communication process ends, in order to ensure communication security, the first quantum public key, the first quantum private key, the second quantum private key, and the second quantum public key are destroyed.
[0097] Based on the above content, the first communication device and the second communication device perform device - to - device interaction. Since the content of the interaction data needs to be kept confidential, using quantum keys in the interaction process can ensure the confidentiality of the device - to - device interaction between the first communication device and the second communication device.
[0098] See Figure 4 , this figure is a flowchart of another method for implementing secure device - to - device communication provided by the embodiment of the present application. This method is used for the situation where the collected communication data exceeds the communication threshold. This method includes:
[0099] S401: When the communication data volume of the data to be encrypted collected exceeds the communication data threshold, generate the first quantum private key and the first quantum public key according to the quantum key.
[0100] In the embodiment of the present application, the situation where the communication data threshold is exceeded includes the following:
[0101] User 1 and User 2 have a high-definition video call. At this time, during the continuous communication interaction process, the communication data exceeds the communication data threshold.
[0102] The quantum key is generated by the first quantum security information device, and the first quantum public key and the first quantum private key are generated from the quantum key.
[0103] S402: Send the first quantum public key to the first communication device so that the first communication device sends the first quantum public key to the second quantum security information device connected to the second communication device.
[0104] In the embodiment of the present application, the first quantum public key is sent to the first communication device. When the first communication device receives the first quantum public key, it sends the first quantum public key to be saved in the second quantum security information device connected to the second communication device.
[0105] S403: Receive the encrypted symmetric key from the first communication device.
[0106] In the embodiment of the present application, the first communication device receives the encrypted symmetric key, where the encrypted symmetric key is generated by the second communication device encrypting the symmetric key random number using the first quantum public key.
[0107] The symmetric key random number is generated by the second quantum security information device connected to the second communication device.
[0108] S404: Decrypt the encrypted symmetric key using the first quantum private key to obtain the symmetric key.
[0109] In the embodiment of the present application, use the first quantum private key generated by the first quantum security information device to decrypt the encrypted symmetric key using the decryption algorithm to obtain the symmetric key.
[0110] S405: When the data to be encrypted is collected, encrypt the data to be encrypted using the symmetric key, generate the third encrypted data and send it to the first communication device so that the first communication device sends the third encrypted data to the second communication device.
[0111] In an embodiment of the present application, after collecting the data to be encrypted, the symmetric key is used to encrypt the data to be encrypted by using an encryption algorithm. After the data is encrypted, the third encrypted data is generated and sent to the first communication device. When the first communication device receives the third encrypted data, the third encrypted data is sent to the second communication device.
[0112] S406: After receiving the fourth encrypted data sent by the second communication device, use the symmetric key to decrypt the fourth encrypted data.
[0113] In an embodiment of the present application, after receiving the fourth encrypted data, the symmetric key is used to decrypt the fourth encrypted data by using a decryption algorithm.
[0114] Wherein, the fourth encrypted data is generated by the second quantum secure information device using the symmetric key.
[0115] S407: After the secure communication process ends, destroy the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key.
[0116] Based on the above, when the communication data volume exceeds the communication data threshold, due to the large amount of data to be interacted, encrypting and decrypting the communication interaction data that is difficult to protect by using the symmetric key can better ensure the data security of the communication interaction.
[0117] See Figure 5 , this figure is an interaction diagram of another method for implementing secure communication between devices provided by an embodiment of the present application:
[0118] In this embodiment, the first communication device and the second communication device perform device-to-device interaction. Since the content of the interaction data needs to be kept confidential and the communication interaction data volume exceeds the communication data threshold, during the communication interaction process, the following steps are included:
[0119] S501: The first quantum secure information device generates a first quantum public key and a first quantum private key.
[0120] S502: After the first communication device receives the first quantum public key sent by the first quantum secure information device, the first quantum public key is sent to the second quantum secure information device for storage.
[0121] S503: The first communication device receives the encrypted symmetric key.
[0122] The encrypted symmetric key is generated by the second quantum secure information device using the first quantum public key to encrypt the symmetric key random number, and the symmetric key random number is generated by the second quantum secure information device connected to the second communication device.
[0123] S504: Decrypt the encrypted symmetric key using the first quantum private key to obtain the symmetric key.
[0124] S505: After receiving the fourth encrypted data sent by the second communication device, decrypt the fourth encrypted data using the symmetric key.
[0125] Wherein, the fourth encrypted data is generated by the second quantum security information device using the symmetric key.
[0126] S506: When the data to be encrypted is collected, encrypt the data to be encrypted using the symmetric key to generate the third encrypted data and send it to the first communication device, so that the first communication device sends the third encrypted data to the second communication device.
[0127] S507: After receiving the fourth encrypted data sent by the second communication device, decrypt the fourth encrypted data using the symmetric key.
[0128] S508: After the secure communication process ends, destroy the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key.
[0129] After the communication process ends, to ensure communication security, the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key are destroyed.
[0130] The above introduces an implementation method for secure communication between devices in an embodiment of the present application. Next, in combination with specific application scenarios, a rational description of the implementation method for secure communication between devices will be given.
[0131] See Figure 6 , which is a flowchart of an implementation method for secure communication between devices in an embodiment of the scenario of the present application. The method includes:
[0132] It should be noted in advance that in the embodiments of this scenario, the first communication device is the first communication device used by User 1, and the second communication device is the second communication device used by User 2. Among them, User 1 and User 2 are the two parties of the users making a call or having a web conference. The first quantum security information device and the second quantum security information device can be in the form of a headset (only for voice calls) according to the needs of the users, or a block device with hardware such as a microphone, an audio playback device, and even a camera and a screen. This device is responsible for collecting the voice information or video information of the users, and playing the information that other users need to transmit. At the same time, it has the capabilities of acting as an authentication device with traditional devices or conference devices and short-range information transmission based on Bluetooth, WiFi, etc. The first communication device and the second communication device are commonly used communication devices in people's lives, mainly including devices such as mobile phones and personal computers.
[0133] It should be noted that the first quantum security information device includes: a key storage unit, an encryption / decryption chip unit, a random number generation unit, a short-range communication unit, and so on.
[0134] S601: The first quantum security information device collects signals such as voice and video to be transmitted by User 1.
[0135] In a possible implementation manner, the acquisition method can be to use MATLAB to collect signals such as voice and video, but it is not limited to the MATLAB acquisition method.
[0136] S602: Use the quantum public key stored in the key storage unit to encrypt the data through the encryption / decryption chip unit.
[0137] The key storage unit is a unit in the quantum security information device, which is used to store the quantum key used in the current voice call, and destroy the key after the call ends.
[0138] The encryption / decryption chip unit mainly runs encryption / decryption and authentication algorithms including hash algorithms, public key cryptography algorithms (such as elliptic curve public key cryptography algorithms, etc.), symmetric cryptography algorithms (such as block cipher algorithms, symmetric cryptosystems in cryptosystems, etc.), and uses the quantum key generated by the quantum random number generation unit to encrypt and decrypt the call or video information.
[0139] In a possible implementation manner, use the quantum public key stored in the key storage unit to encrypt the data through the hash algorithm of the encryption / decryption chip unit.
[0140] S603: Transmit the encrypted data to the first communication device through the short-range communication unit.
[0141] In a possible implementation manner, after the first communication device receives the encrypted data, the first communication device uses a traditional communication network such as a public wireless network or an optical fiber network in the short-range communication unit to send the public key to the first communication device.
[0142] S604: The first communication device uses a network to transmit the encrypted data to the second communication device.
[0143] In a possible implementation manner, after the first communication device receives the second quantum public key, it sends the second quantum public key to the first quantum security information device for storage.
[0144] S605: The second quantum security information device receives the encrypted information sent by the second communication device, decrypts the encrypted data, and plays it to User 2.
[0145] In a possible implementation manner, the second quantum security information device decrypts the encrypted data using a hash algorithm and converts the decrypted data into voice or video to play to User 2.
[0146] S606: The second quantum security information device collects signals such as voice and video to be transmitted by User 2.
[0147] In a possible implementation manner, the acquisition method may be to use MATLAB to collect signals such as voice and video, but it is not limited to the MATLAB acquisition method.
[0148] S607: Use the quantum public key stored in the key storage unit to encrypt the data through the encryption and decryption chip unit.
[0149] The key storage unit is a unit in the quantum security information device, which is used to store the quantum key used in the current voice call and destroy the key after the call ends.
[0150] The encryption and decryption chip unit mainly runs encryption and decryption and authentication algorithms including hash algorithms, public key cryptography algorithms (such as elliptic curve public key cryptography algorithms, etc.), symmetric cryptography algorithms (such as block cipher algorithms, symmetric cryptography systems in the cryptographic system, etc.), etc., and uses the quantum key generated by the quantum random number generation module to encrypt and decrypt voice call or video information.
[0151] In a possible implementation manner, use the quantum public key stored in the key storage unit to encrypt the data through the hash algorithm of the encryption and decryption chip unit.
[0152] S608: Transmit the encrypted data to the second communication device through the short-range communication unit.
[0153] In a possible implementation, after the second communication device receives the encrypted data, the second communication device uses a traditional communication network such as a public wireless network or an optical fiber network to send the public key to the second communication device.
[0154] S609: The second communication device uses a network to transmit the encrypted data to the second communication device.
[0155] In a possible implementation, after the second communication device receives the first quantum public key, it sends the first quantum public key to the second quantum security information device for storage.
[0156] S610: The first quantum security information device decrypts the encrypted data and plays it to User 1.
[0157] In a possible implementation, the first quantum security information device decrypts the encrypted data using a hash algorithm and converts the decrypted data into voice or video to play to User 1.
[0158] S611: After the call or meeting ends, both devices destroy all quantum keys used during the call process at this time.
[0159] In this step, to ensure the security of the communication between both parties, both devices will destroy all quantum keys used during the call process at this time. When establishing a connection next time, the data channel establishment process will be carried out again to ensure the security of the communication.
[0160] Based on the above content, it can be seen that in the embodiment of the present application, after the encryption and decryption operations in the quantum security information device for the communication interaction between User 1 and User 2, a data channel is established, and subsequent communication interaction steps are executed in the data channel, greatly improving the confidentiality of the communication interaction and ensuring the security.
[0161] See Figure 7 , this figure is a schematic structural diagram of a device for realizing secure communication between devices provided by the embodiment of the present application. The device includes: a generating unit 701, a sending unit 702, a receiving unit 703, a decrypting unit 704, and an encrypting unit 705.
[0162] The generating unit 701 is configured to generate a quantum random number as a quantum key, and generate a first quantum private key and a first quantum public key according to the quantum key.
[0163] The sending unit 702 is configured to send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to the second quantum security information device connected to the second communication device.
[0164] A receiving unit 703, configured to receive a second quantum public key from the first communication device, where the second quantum public key is sent by the second quantum security information device to the first communication device through the second communication device.
[0165] A decrypting unit 704, configured to decrypt the second encrypted data using the first quantum private key after receiving the second encrypted data sent by the second communication device, where the second encrypted data is generated by the second quantum security information device using the first quantum public key.
[0166] An encrypting unit 705, configured to encrypt the data to be encrypted using the second quantum public key when the data to be encrypted is collected, generate a first encrypted data and send it to the first communication device, so that the first communication device sends the first encrypted data to the second quantum security information device.
[0167] In a possible implementation manner, the apparatus further includes:
[0168] A data channel establishing unit 706, configured to authenticate whether the user corresponding to the first communication device is legal after the first quantum security information device is connected to the first communication device, and if the user is legal, establish a data channel with the first communication device.
[0169] In a possible implementation manner, the apparatus further includes:
[0170] A transmission unit exceeding threshold 707, configured to:
[0171] When the communication data volume of the data to be encrypted collected exceeds a communication data threshold, generate the first quantum private key and the first quantum public key according to the quantum key.
[0172] Send the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to a second quantum security information device connected to a second communication device.
[0173] Receive an encrypted symmetric key from the first communication device, where the encrypted symmetric key is generated by the second quantum security information device using the first quantum public key to encrypt a symmetric key random number, and the symmetric key random number is generated by the second quantum security information device connected to the second communication device.
[0174] Decrypt the encrypted symmetric key using the first quantum private key to obtain a symmetric key.
[0175] When the data to be encrypted is collected, use the symmetric key to encrypt the data to be encrypted, generate the third encrypted data, and send it to the first communication device, so that the first communication device sends the third encrypted data to the second communication device.
[0176] After receiving the fourth encrypted data sent by the second communication device, use the symmetric key to decrypt the fourth encrypted data, where the fourth encrypted data is generated by the second quantum security information device using the symmetric key.
[0177] In a possible implementation, the device further includes:
[0178] The first destruction unit 708 is configured to destroy the first quantum public key, the first quantum private key, the second quantum public key, and the second quantum private key when it is determined that the device secure communication process ends.
[0179] In a possible implementation, the device further includes:
[0180] The second destruction unit 709 is configured to destroy the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key when it is determined that the device secure communication process ends.
[0181] In a possible implementation, the generating unit 701 includes:
[0182] An algorithm sub-unit is configured to use algorithms including a hash algorithm, a public key cryptography algorithm, and / or a symmetric cryptography algorithm to generate a first quantum private key and a first quantum public key according to the quantum key.
[0183] See Figure 8 , which is a schematic diagram of the corresponding device and computer storage medium provided by the embodiments of the present application, including:
[0184] Among them, the device includes a memory 801 and a processor 802. The memory 801 is used to store instructions or codes, and the processor 802 is used to execute the instructions or codes so that the device executes the method for secure communication between devices according to any embodiment of the present application.
[0185] It should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0186] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in a software module executed by a processor, or in a combination thereof. The software module may be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0187] The foregoing description of the disclosed embodiments enables those skilled in the art to make or use the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Thus, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for implementing secure communication between devices, characterized in that, The method is applied to a first quantum-secure information device, which is connected to a first communication device. The method includes: Generating a quantum random number as a quantum key, and generating a first quantum private key and a first quantum public key according to the quantum key; Sending the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to a second quantum-secure information device connected to a second communication device; Receiving a second quantum public key from the first communication device, where the second quantum public key is sent by the second quantum-secure information device to the first communication device through the second communication device; When receiving the second encrypted data sent by the second communication device, decrypting the second encrypted data using the first quantum private key, where the second encrypted data is generated by the second quantum-secure information device using the first quantum public key; When collecting data to be encrypted, encrypting the data to be encrypted using the second quantum public key, generating first encrypted data and sending it to the first communication device, so that the first communication device sends the first encrypted data to the second quantum-secure information device; The method further includes: when the communication data volume of the data to be encrypted collected exceeds a communication data threshold, generating the first quantum private key and the first quantum public key according to the quantum key; Sending the first quantum public key to the first communication device, so that the first communication device sends the first quantum public key to a second quantum-secure information device connected to a second communication device; Receiving an encrypted symmetric key from the first communication device, where the encrypted symmetric key is generated by the second quantum-secure information device using the first quantum public key to encrypt a symmetric key random number, and the symmetric key random number is generated by the second quantum-secure information device connected to the second communication device; Decrypting the encrypted symmetric key using the first quantum private key to obtain the symmetric key; When collecting data to be encrypted, encrypting the data to be encrypted using the symmetric key, generating third encrypted data and sending it to the first communication device, so that the first communication device sends the third encrypted data to the second communication device; When receiving the fourth encrypted data sent by the second communication device, decrypting the fourth encrypted data using the symmetric key, where the fourth encrypted data is generated by the second quantum-secure information device using the symmetric key.
2. The method according to claim 1, wherein The method further includes: After the first quantum-secure information device is connected to the first communication device, authenticating whether the user corresponding to the first communication device is legal. If the user is legal, establishing a data channel with the first communication device.
3. The method according to claim 1, wherein The method further includes: When it is determined that the device secure communication process ends, destroying the first quantum public key, the first quantum private key, the second quantum public key, and the second quantum private key.
4. The method according to claim 1, wherein The method further includes: When it is determined that the device secure communication process ends, destroying the first quantum public key, the first quantum private key, the encrypted symmetric key, and the symmetric key.
5. The method according to claim 1, wherein Generating a first quantum private key and a first quantum public key based on the quantum key, including: Using a hash algorithm, a public key cryptography algorithm, and / or a symmetric cryptography algorithm to generate a first quantum private key and a first quantum public key based on the quantum key.
6. A device for realizing secure communication between devices, characterized in that, Applied to a first quantum security information device, the first quantum security information device being connected to a first communication device, the apparatus including: A generating unit for generating a quantum random number as the quantum key and generating a first quantum private key and a first quantum public key based on the quantum key; A sending unit for sending the first quantum public key to the first communication device so that the first communication device sends the first quantum public key to a second quantum security information device connected to a second communication device; A receiving unit for receiving a second quantum public key from the first communication device, the second quantum public key being sent by the second quantum security information device to the first communication device through the second communication device; A decrypting unit for decrypting the second encrypted data using the first quantum private key when the second encrypted data sent by the second communication device is received, the second encrypted data being generated by the second quantum security information device using the first quantum public key; An encrypting unit for encrypting the data to be encrypted using the second quantum public key when the data to be encrypted is collected, generating first encrypted data and sending it to the first communication device so that the first communication device sends the first encrypted data to the second quantum security information device; The apparatus further includes: an over-threshold sending unit for generating the first quantum private key and the first quantum public key based on the quantum key when the communication data volume of the data to be encrypted collected exceeds a communication data threshold; Sending the first quantum public key to the first communication device so that the first communication device sends the first quantum public key to a second quantum security information device connected to a second communication device; Receiving an encrypted symmetric key from the first communication device, the encrypted symmetric key being generated by the second quantum security information device using the first quantum public key to encrypt a symmetric key random number, the symmetric key random number being generated by a second quantum security information device connected to a second communication device; Decrypting the encrypted symmetric key using the first quantum private key to obtain the symmetric key; When the data to be encrypted is collected, encrypting the data to be encrypted using the symmetric key, generating third encrypted data and sending it to the first communication device so that the first communication device sends the third encrypted data to the second communication device; When the fourth encrypted data sent by the second communication device is received, decrypting the fourth encrypted data using the symmetric key, the fourth encrypted data being generated by the second quantum security information device using the symmetric key.
7. The device according to claim 6, characterized in that, The apparatus further includes: A data channel unit is established to authenticate whether the user corresponding to the first communication device is legal after the first quantum secure information device is connected to the first communication device. If the user is legal, a data channel with the first communication device is established.
8. A device for implementing secure communication between devices, characterized in that, It includes: A memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for realizing secure communication between devices as described in any one of claims 1-5 is implemented.
Citation Information
Patent Citations
KR20210104337A